PT-2021-4363 · Moxa · Moxa Mxview Network Management
Noam Moshe
·
Published
2021-10-05
·
Updated
2022-10-25
·
CVE-2021-38454
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa MXview Network Management software versions 3.x through 3.2.2
Description
The issue is related to insufficient access control in the Moxa MXView network control software, which can be exploited by a remote attacker to bypass security restrictions using the MQTT protocol. A path traversal vulnerability may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Recommendations
For versions 3.x through 3.2.2, update to a version that addresses the path traversal vulnerability to prevent attackers from creating or overwriting critical files.
As a temporary workaround, consider restricting access to the MQTT protocol to minimize the risk of exploitation.
Avoid using the vulnerable version of the Moxa MXview Network Management software until a patch is available.
Fix
Improper Access Control
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Mxview Network Management